Associate Director of Information Security GRC

Knights of Columbus

New Haven (CT)

Hybrid

USD 112,000 - 191,000

Full time

9 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

401(k) retirement plan with company-m匹
Health insurance options
Paid holidays and generous leave

Job summary

Knights of Columbus is seeking an Associate Director of Governance, Risk, and Compliance (GRC) to lead the information security GRC program, align with regulatory requirements, and report to the Deputy CISO. You will partner with Legal, Privacy, Compliance, IT, and Audit to improve policies, risk management, and governance across the organization.

The role requires five years in GRC, strong analytical and documentation skills, and CIS/CISM/CRISC/CISA certifications preferred.

Qualifications

  • Five years of relevant experience within the Governance, Risk, and Compliance field.
  • Proven working experience performing the functions listed under the core responsibilities section.
  • Bachelor’s degree in information security, Cyber Security, Computer Science, or another related field.

Responsibilities

  • Lead, develop, mentor, and retain a high-performing Information Security GRC team.
  • Establish team objectives, performance measures, responsibilities, and development plans.
  • Develop, maintain, and improve the information security governance, risk, and compliance strategy and multi-year roadmap.
  • Keep up with ongoing trends in the GRC community and ensure up-to-date practices.
  • Develop and maintain information security policies and standards.
  • Coordinate with related functions to ensure security standards are practical and aligned.
  • Maintain the information security risk register and exception processes.
  • Align information security risk with the broader enterprise risk framework.
  • Develop and maintain an information security control framework.
  • Oversee compliance activities related to applicable laws and standards.
  • Coordinate and manage audits, assessments, and examinations.
  • Serve as primary liaison for Internal Audit, External Audit, and regulators.
  • Establish indicators, dashboards, and security maturity measures.
  • Develop third-party risk activities.
  • Governance for new technologies and major initiatives.
  • Partner with Privacy, Legal, and Compliance on overlapping requirements.
  • Stay aware of cybersecurity regulation changes and impact.

Skills

Governance, Risk, and Compliance
Complex information processing
Documentation & workflows
Multi-tasking
Communication skills
NIST CSF knowledge
Deadline-driven
Legal & regulatory standards (NYDFS,GD
CISSP
CISM
CRISC
CISA

Education

Bachelor’s degree in information security / Cyber Security / Computer Science

Job description

Feel Good About Doing Good

The Knights of Columbus is a tax-exempt Catholic fraternal benefit society that provides financial security to members and their families through our life insurance, long-term care insurance, disability income insurance, investment and annuity products. Charity is at the core of our missions: our profits are donated to help those in need and to support our faith - $1.73B over the past ten years. While we have many employees who are not Catholic, we follow the Church’s teachings in our investment strategies and our employee benefits. As part of our religious mission, we support the pro-life cause by contributing to the March for Life and pregnancy resource centers, we oppose assisted suicide and euthanasia, we are evangelists for the Catholic faith, and we help Christians who are facing religious persecution in the Middle East. We all work together to support our two million members as they volunteer to help others in their parishes and communities around the world.

Share Your Talent. Live Your Purpose.

We are a growing and purpose-driven community of professionals. Join us to discover how you can meet your goals and ours!

Overview

The Associate Director of Governance, Risk, and Compliance (GRC) is a resourceful and experienced information security leader responsible for managing, and continuously improving, the organization’s information security GRC program. This position provides strategic direction and operational oversight for the organization’s information security governance framework, including the development and maintenance of security policies, standards, and procedures; coordination of security audits and assessments; management of information security risks and exceptions; oversight of third-party security risk; and delivery of meaningful program reporting to leadership and governance committees. The Associate Director ensures that the organization’s information security governance practices remain aligned with applicable regulatory requirements, contractual obligations, industry standards, and organizational risk objectives. This individual reports to, and works closely with, the Deputy CISO and partners across the organization with Enterprise Risk Management, Internal Audit, Legal, Privacy, Compliance, Information Technology, and other business leaders to promote effective governance, strengthen risk management, and support the continuous improvement of the information security program.

Core Responsibilities
  • Lead, develop, mentor, and retain a high-performing Information Security GRC team.
  • Establish team objectives, performance measures, responsibilities, and development plans.
  • Develop, maintain, and continuously improve the organization’s information security governance, risk, and compliance strategy, operating model, and multi-year roadmap.
  • Keep up with ongoing trends and changes within the GRC community and make sure that the organization is up-to-date with the latest relevant methods and practices.
  • Develop, maintain, and manage information security policies and standards.
  • Partner with colleges within Information Security, technology and other function areas to ensure security standards are practical, measurable, and aligned with organizational requirements.
  • Maintain the information security risk register and exception process to ensure security risks are appropriately documented, assigned, prioritized, tracked, and reported.
  • Partner with Enterprise Risk Management to align information security risk methodologies, reporting, and governance with the organization’s broader enterprise risk management framework.
  • Develop and maintain an information security control framework aligned with applicable regulatory requirements, contractual obligations, industry standards, and organizational risk priorities.
  • Oversee information security compliance activities related to applicable laws, regulations, standards, frameworks, and customer requirements, which may include NY-DFS, COBIT, various NIST frameworks, amongst others.
  • Coordinate and manage information security audits, assessments, and examinations.
  • Serve as the primary Information Security liaison for Internal Audit, External Audit, and other regulatory examiners.
  • Establish key indicators, reports, dashboards, control metrics, and security maturity measures to assess the effectiveness of the information security program.
  • Develop, maintain, and manage information security third-party risk activities.
  • Establish governance processes to evaluate security risks associated with new technologies, major business initiatives, cloud services, significant system changes, and strategic projects.
  • Partner with Privacy, Legal, and Compliance to address overlapping security, privacy, regulatory, and contractual requirements.
  • Maintain awareness of changes to cybersecurity laws, regulations, standards, industry expectations, and emerging risk trends, and assess their potential impact on the organization.
Skills Qualifications

Required:

  • Extensive knowledge of Governance, Risk, and Compliance practices
  • Ability to process and understand complex information relevant to cyber security initiatives
  • Ability to create detailed documentation and workflow diagrams
  • Possess the ability to multi-task between projects
  • Exceptional written, oral, and interpersonal communication skills
  • Understanding of the NIST CSF framework and other associated cyber security standards
  • Ability to drive team outcomes through tight deadlines and prioritization of tasks
  • Extensive knowledge of legal and regulatory compliance standards and requirements such as NYDFS, GDPR, CCRA, and CCPA.

Preferred:

  • CISSP, CISM, CRISC, CISA or other security management certifications
Education

Required:

  • Five years of relevant experience within the Governance, Risk, and Compliance field.
  • Proven working experience performing the functions listed under the core responsibilities section.

Preferred:

  • Bachelor’s degree in information security, Cyber Security, Computer Science, or another related field
  • Insurance and financial services industry experience is a plus
Compensation

The wage range for this role takes into account a broad array of factors that are considered in making compensation decisions, including but not limited to: skill sets; experience and training; licensure and certifications; and other business and organizational needs. The range below applies as long as the work is performed in Connecticut; the Knights of Columbus reserves the right to adjust the wage range if the position is performed in another location. At the Knights of Columbus, it is not typical for an individual to be hired at or near the top of the range for their role, and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $112,000 - $190,500.

Authorization To Work In The United States Is Required

This position is not eligible for visa sponsorship.

Physical Demands

Must be able to remain in a stationary position for a majority of the workday.

KofC Cares

Our mission is focused on family and faith, and we support our employees in seeking a balanced life.

Employee Benefits

Time Away: 13 paid holidays per year in addition to vacation and paid sick leave, and flexible workweek schedules.

Professional Development: Certifications, designation, and tuition reimbursement.

Retirement Benefits: 401(k) retirement savings plan with matching company contributions, and cash balance retirement plans fully funded by the company.

Health and Wellness:

  • Short-term disability and term life insurance fully paid for by the company;
  • Up to 12 weeks of childbirth leave under STD policy.
  • One week of fully paid parental leave for all new parents, including adoptive and foster parents.
  • A variety of health insurance options, including premium-level family coverage and a pre-tax Health Savings Account with employer contributions. The Order's health plans do not cover abortion, sterilization, or contraception, and the Order has helped advocate for other employers who do not want to provide coverage.
  • Long-term disability insurance;
  • Dental insurance;
  • Vision insurance;
  • Health club membership reimbursement;
  • Employee Assistance Program
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Investment Advisor II
Investment Advisor II

Knights of Columbus • Boston (MA)

On-site
USD 121,000 - 205,000
13 paid holidays per year
401(k) matching
Tuition reimbursement
+1
Senior Applied AI & Data Scientist
Senior Applied AI & Data Scientist

Knights of Columbus • New Haven (CT)

On-site
USD 122,000 - 207,500
13 paid holidays
401(k) with matching contributions
Flexible workweek schedules
+2
Client Service & Operations Associate
Client Service & Operations Associate

Knights of Columbus • Boston (MA)

On-site
USD 59,000 - 100,000
401(k) retirement savings with company
Health insurance
Paid holidays
+1
Major Gift Officer, Planned Giving
Major Gift Officer, Planned Giving

Knights of Columbus • New Haven (CT)

On-site
USD 110,000 - 187,000
Time away: 13 paid holidays + vacation
Flexible workweek schedules
Tuition reimbursement for professional
+5
Field Performance Specialist
Field Performance Specialist

Knights of Columbus • United States

On-site
USD 90,000 - 140,000
Paid holidays
Tuition reimbursement
401(k) matching
+5
Senior Business Systems Analyst
Senior Business Systems Analyst

Knights of Columbus • New Haven (CT)

On-site
USD 98,000 - 166,500
401(k) retirement savings plan
Paid parental leave
Flexible workweek schedules
+2
Senior Information Security GRC Director
Senior Information Security GRC Director

Knights of Columbus • New Haven (CT)

Hybrid
USD 112,000 - 191,000
401(k) retirement plan with company-m匹
Health insurance options
Paid holidays and generous leave
Cybersecurity Supervisor
Cybersecurity Supervisor

NKSFB • Los Angeles (CA)

Hybrid
USD 120,000 - 150,000
PTO 15 days annually
401(k) employer match
10 holidays + floating holiday
+8
Director ETL and Data Engineering
Director ETL and Data Engineering

Church Pension Group • New York (NY)

Hybrid
USD 136,000 - 180,000
Medical (including Vision)
Dental
Pension plan
+2
Manager, Infrastructure Governance
Manager, Infrastructure Governance

RXinsider LTD. • Kentucky

On-site
USD 125,000 - 179,000
Medical, dental and vision coverage
401k plan
Paid time off
+1